Taxonomy of Security-related Issues in Android Apps: An Empirical Study

被引:0
|
作者
Das, Teerath [1 ]
Ali, Adam [2 ]
Mikkonen, Tommi [1 ]
机构
[1] Univ Jyvaskyla, Fac Informat Technol, Jyvaskyla, Finland
[2] Mohammad Ali Jinnah Univ, Fac Comp, Karachi, Pakistan
关键词
Android Apps; Security Issues; Taxonomy; Card sorting;
D O I
10.1145/3695750.3695824
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Smart applications (apps) have become the primary means of obtaining digital services in many aspects of our daily lives, such as health care, e-banking, online shopping, etc. With the growing number of smart apps being created, the likelihood of security vulnerabilities has increased significantly. Smartphone developers remain vigilant about security concerns during their mobile app development, installation, and maintenance. This paper presents a large-scale empirical study examining critical security issues in open-source Android apps obtained from GitHub. We analyzed 111,224 commits across 2,187 apps and identified 689 commits explicitly related to security issues. Additionally, we utilized the card-sorting approach to construct a taxonomy/catalog of ten distinct categories of security-related issues. According to our findings, the most frequent security-related problem in our dataset was related to permission issues, accounting for 370 instances (53.7%), followed by Login, with 160 instances, representing 23.22%. On the other hand, Privacy and Framework issues were less frequent, with only 5 (0.72%) and 3 (0.43%) instances, respectively, in our dataset. Moreover, our taxonomy also included 71 sub-categories/sub-themes, with permission issues having the highest number of sub-categories (23) and Framework issues with the lowest numbers (2). Developers discussed permission sub-categories, such as camera permission, WiFi permissions, storage permission, WRITE/READ_PHONE_STATE permission, and location permission, among others, in their code commits. The insights gained from our study provide a foundation for comprehending the primary security concerns from the viewpoints of both researchers and software practitioners.
引用
收藏
页码:8 / 14
页数:7
相关论文
共 50 条
  • [21] Forensic taxonomy of android productivity apps
    Abdullah Azfar
    Kim-Kwang Raymond Choo
    Lin Liu
    Multimedia Tools and Applications, 2017, 76 : 3313 - 3341
  • [22] Forensic taxonomy of android productivity apps
    Azfar, Abdullah
    Choo, Kim-Kwang Raymond
    Liu, Lin
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (03) : 3313 - 3341
  • [23] Forensic Taxonomy of Android Social Apps
    Azfar, Abdullah
    Choo, Kim-Kwang Raymond
    Liu, Lin
    JOURNAL OF FORENSIC SCIENCES, 2017, 62 (02) : 435 - 456
  • [24] An Empirical Analysis of Security and Privacy Risks in Android Cryptocurrency Wallet Apps
    Sentana, I. Wayan Budi
    Ikram, Muhammad
    Kaafar, Mohamed Ali
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PT II, ACNS 2023, 2023, 13906 : 699 - 725
  • [25] An empirical study of configuration changes and adoption in Android apps
    Jha, Ajay Kumar
    Lee, Sunghee
    Lee, Woo Jin
    JOURNAL OF SYSTEMS AND SOFTWARE, 2019, 156 : 164 - 180
  • [26] Vulnerability Detection in Recent Android Apps: An Empirical Study
    Shezan, Faysal Hossain
    Afroze, Syeda Farzia
    Iqbal, Anindya
    PROCEEDINGS OF 2017 INTERNATIONAL CONFERENCE ON NETWORKING, SYSTEMS AND SECURITY (NSYSS), 2017, : 55 - 63
  • [27] Learning to Identify Security-Related Issues Using Convolutional Neural Networks
    Palacio, David N.
    McCrystal, Daniel
    Moran, Kevin
    Bernal-Cardenas, Carlos
    Poshyvanyk, Denys
    Shenefiel, Chris
    2019 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2019), 2019, : 140 - 144
  • [28] Update on security-related lawsuits
    Schultz, E
    COMPUTERS & SECURITY, 2005, 24 (06) : 430 - 431
  • [29] An empirical analysis of android apps bug and automated testing approach for Android apps
    Bie Y.
    Bin S.
    Sun G.
    Zhou X.
    1600, Science and Engineering Research Support Society (11): : 1 - 10
  • [30] Forensic Taxonomy of Popular Android mHealth Apps
    Azfar, Abdullah
    Choo, Kim-Kwang Raymond
    Liu, Lin
    AMCIS 2015 PROCEEDINGS, 2015,